Alert · reviewed · open
The entity's first transfer, $2,357.31, above the program median, came 0.0 hours after verification.
- Detector
- rapid_onboarding
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_59yo4ag6ckh
- Transfer
- acht_sim_lant_59yo4ag6ckh · $2,357.31 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired for rapid_onboarding on transfer acht_sim_lant_59yo4ag6ckh, a $2,357.31 ACH outgoing credit from entity Grove Co 36 in the Lantern Lending program. The transfer was the entity's first, occurred 0.0 hours after verification, and exceeded the program median of $1,134.16.
What the evidence shows. The transfer has settled with no return code, indicating no rail-level failure. The entity is a verified US business, not high risk, not PEP, with no open review reasons and screening current as of 2026-06-28. Signals attached to the transfer are counterparty.first_time and counterparty.first_time_and_large, both expected outcomes of a first transaction exceeding the median. The detector's own hard_signal flag is false, and the transfer/entity score bands are unscored due to n=1, so no statistical confidence can be assigned. Program KRIs show no elevated risk: frozen_accounts, overdraft_events, stale_screening_share, high_risk_entity_share, and verification_denial_rate are all in normal ('ok') range; pep_flagged_entities is at 'watch' but this entity is not PEP-flagged. Several KRIs (hold_aging_hours, manual_review_rate, velocity_vs_declared, etc.) are unmeasured (n=0), limiting broader context. There are no prior dispositions on this entity or transfer.
What was checked. Transfer status and return code, entity verification status and screening date, program declared volume versus transfer size, program KRIs for elevated risk indicators, and prior disposition history.
What is recommended. The transfer has already settled, so there is no held position to release or continue holding. The amount is modestly above median for a first transaction from a verified, non-high-risk US business with current screening, and no other red flags (high risk, PEP, adverse review reasons, prior alerts) are present. The evidence does not indicate a pattern requiring escalation, only a single data point (n=1) with an unscored band. This can be closed, with the caveat that confidence is limited by the single-transaction sample and null scoring.
- Recommendation
- close
- Confidence
- 0.58
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer status is SETTLED with no return code; no funds are pending action.
- Entity is VERIFIED, non-high-risk, non-PEP, with no open review reasons and screening current within the last three months.
- Detector hard_signal is false and transfer/entity bands are unscored (n=1, confidence null), indicating this is a single low-confidence data point rather than a confirmed pattern.
- Program KRIs relevant to fraud/risk exposure (frozen_accounts, overdraft_events, stale_screening_share, high_risk_entity_share, verification_denial_rate) are all within normal range.
- No prior dispositions exist on this entity or transfer to suggest recurring concern.
- Transfer amount ($2,357.31) is roughly double the program median but not disproportionate to the program's declared $900,000 monthly volume.
Evidence
{
"n": 1,
"band": "unscored",
"skoor": null,
"typology": "rapid_onboarding",
"confidence": null,
"thresholds": {
"hours": 24
},
"medianCents": "113416",
"routeReason": "detector not auto-closable",
"hoursSinceVerification": 0
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| counterparty.first_time | +10 | first transfer with this counterparty | |
| counterparty.first_time_and_large | +15 | amount above the program p95 (172886) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.